LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Ivanti

9 CVEs published in the last four months and 1 stories. Exploited flaws first.

Critical3
High6
Medium0
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-10520exploited10criticalstandalone sentryAn OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a r88d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-10520exploited10criticalstandalone sentryAn OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a r88d ago
CVE-2026-105239.9criticalstandalone sentryAn Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions88d ago
CVE-2026-80439.6criticalxtractionExternal control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to116d ago
CVE-2026-89928.8highsecure access clientAn improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unaut106d ago
CVE-2026-81118.8highendpoint managerSQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated a116d ago
CVE-2026-74327.8highsecure access clientA race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privi116d ago
CVE-2026-81107.8highendpoint managerIncorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local aut116d ago
CVE-2026-149037.7highxtractionPath traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrar53d ago
CVE-2026-80517.2highvirtual traffic managerOS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker116d ago

Filter the full tracker by Ivanti

Our coverage of Ivanti

breach

Ivanti EPM Update Patches Remotely Exploitable Flaws

The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek.